REDHAT-BUG-2380949: High severity Nlnet Labs Unbound vulnerability

Published Jul 16, 2025
·
Updated

A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is also vulnerable when compiled with ECS support, i.e., '--enable-subnet', AND configured to send ECS information along with queries to upstream name servers, i.e., at least one of the 'send-client-subnet', 'client-subnet-zone' or 'client-subnet-always-forward' options is used. Resolvers supporting ECS need to segregate outgoing queries to accommodate for different outgoing ECS information. This re-opens up resolvers to a birthday paradox attack (Rebirthday Attack) that tries to match the DNS transaction ID in order to cache non-ECS poisonous replies.

Affected Software

1 affected component
Nlnet Labs Unbound

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Rebuild Unbound without ECS support by not compiling with '--enable-subnet' (to avoid the Rebirdtable Attack when ECS is used).

    Unbound --enable-subnet (ECS support at compile time) = disabled
  2. Configuration

    If Unbound is compiled with ECS support ('--enable-subnet'), configure it so it does not send ECS to upstream resolvers by ensuring none of these options are used: 'send-client-subnet', 'client-subnet-zone', or 'client-subnet-always-forward'.

    Unbound ECS forwarding options (send-client-subnet / client-subnet-zone / client-subnet-always-forward) = do not send ECS to upstream
  3. Compensating control

    For caching resolvers that support EDNS Client Subnet (ECS), segregate outgoing queries to accommodate different outgoing ECS information so that non-ECS poisoned replies are not cached for ECS-disabled or differing ECS contexts.

Event History

Jul 16, 2025
Data Sourced
via Red Hat·03:02 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2380949?

The severity of REDHAT-BUG-2380949 is classified as high due to the potential for cache poisoning attacks.

2

How do I fix REDHAT-BUG-2380949?

To fix REDHAT-BUG-2380949, upgrade to the latest version of Unbound that addresses this vulnerability.

3

Which versions of Unbound are affected by REDHAT-BUG-2380949?

Unbound compiled with EDNS Client Subnet support and configured to send ECS information is vulnerable to REDHAT-BUG-2380949.

4

What systems are impacted by REDHAT-BUG-2380949?

Systems running Unbound with ECS enabled and configured to send ECS data in DNS queries are impacted by REDHAT-BUG-2380949.

5

Is there a workaround for REDHAT-BUG-2380949?

A temporary workaround for REDHAT-BUG-2380949 is to disable ECS support in Unbound until a patch is applied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203